In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS issues but were insufficient.
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2022-11-01T22:32:49Z",
"nvd_published_at": "2017-06-12T16:29:00Z",
"severity": "MODERATE"
}